CVE-2026-77504
Microsoft Office Word Remote Code Execution Vulnerability
Description
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
In plain language
AI Act nowCVE-2026-77504 is a serious Microsoft Office Word flaw that can let an attacker run code over the network on affected Windows systems—so a typical small business should act quickly and update.
CVE-2026-77504 is an Office Word remote code execution issue driven by a memory-safety flaw (CWE-415) that can be triggered via a crafted Word document/message to achieve code execution over a network; it is not listed in CISA KEV and no public exploit code is on record.
What to do now
- Check whether your business uses Microsoft Office Word on the affected Windows versions (Windows 10/11 and Windows Server listed) and whether those systems have Microsoft updates pending.
- Identify your exact Windows version and build number, then confirm you are below the fixed build listed for that branch.
- Install the Microsoft update for CVE-2026-77504 from the Microsoft update guide and reboot when prompted.
- After updating, test opening a typical internal Word document workflow (email attachment previews included) to ensure normal operation, and verify the system remains patched afterward.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:RUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows zero-day
- Microsoft and Adobe Patch Tuesday, September 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Microsoft Exchange Server Qualys
- Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysen-us·BleepingComputer· Exploited Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-77504 and every CVE in our database. Create a free account — no credit card required.
Create Free Account